HIGH🇬🇧 English

CVE-2026-32107

CVSS 8.8v3.1pub. 2026-04-17upd. 2026-04-27

xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated local attacker to escalate privileges to root and execute arbitrary code on the system. An additional exploit would be needed to facilitate this. This issue has been fixed in version 0.10.6.

oryginał EN
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Neutrinolabs Xrdp

    APP
    Neutrinolabs
    < 0.10.6
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCELPE
CWE
Referencje

Powiązane podatności

CVE-2026-41252CRITICAL9.8PL ✓ten sam produkt

xrdp: heap buffer overflow w trybie vnc-any umożliwiający RCE przed uwierzytelnieniem

CVE-2026-32105CRITICAL9.3PL ✓ten sam produkt

Brak weryfikacji podpisu MAC w Xrdp — podatność MITM w Classic RDP Security

CVE-2025-68670CRITICAL9.1PL ✓ten sam produkt

Nieuwierzytelniony stack-based buffer overflow w xrdp (RCE)

CVE-2022-23478CRITICAL9.1PL ✓ten sam produkt

Out of Bound Write w xrdp — zapis poza granicami bufora przez RDP

CVE-2022-23477CRITICAL9.1PL ✓ten sam produkt

Buffer overflow w xrdp — funkcja audin_send_open()